Project Risk Score Project Risk Score: weighted blend of vulnerability (40%), trust (30%), and pipeline (30%) subscores. Useful for at-a-glance triage. Click for more →
80 /100
Critical

283 findings across 58 packages · 1680 packages clean

Candidates: 46 auto-merge · 37 review · 0 decline · 7 no fix

Scanned axios/axios @ main Scan · Completed 215 hrs ago Download SBOM
Total Findings
283
All detected issues
KEV Findings
0
Known exploited
High EPSS
2
Likely to be exploited
Auto-merge ready
46
Remediation candidates
Affected pkgs
58
with remediation paths
KEV catalog CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more →
0
actively exploited CVEs
Highest EPSS Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
22.4%
CVE-2021-23337
Active vetos
47
lens blocks on candidates

Findings

lodash @ 4.17.21
root → sinon → @sinonjs/formatio → @sinonjs/samsam → lodash
3 findings high–medium
Trust 0/100 EPSS 22.4% ↑
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-r5fr-rjxr-66jc high CVSS 8.1 EPSS 22.4%
lodash vulnerable to Code Injection via `_.template` imports key names
GHSA-f23m-r3pf-42rh medium CVSS 6.5 EPSS 1.5%
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
GHSA-xxjr-mmjv-4gpg medium CVSS 6.5 EPSS 1.5%
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
4.17.21 → 4.18.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 8.1 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

Upgrade lodash from 4.17.21 to 4.18.0 or later

View advisory
root → sinon → @sinonjs/formatio → @sinonjs/samsam → lodash

Blast radius

Paths from project root to lodash - which dependencies pulled this package in?

tar @ 2.2.2 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → dtslint → @definitelytyped/utils → tar
58 findings high–medium
Trust 0/100 EPSS 15.0% ↑ ⚠ ownership transferred
MIXED
GHSA-r6q2-hw4h-h46w high CVSS 8.8 EPSS 0.2%
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Affects 5 install paths

GHSA-3jfq-g458-7qm9 high CVSS 8.3 EPSS 15.0%
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
GHSA-5955-9wpr-37jh high CVSS 8.3 EPSS 1.3%
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
GHSA-34x7-hfp2-rc4v high CVSS 8.2 EPSS 0.5%
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Affects 5 install paths

GHSA-23hp-3jrh-7fpw high CVSS 7.5 EPSS 0.4%
node-tar: Decompression/parse DoS via unlimited input

Affects 5 install paths

GHSA-8qq5-rm4j-mr97 high CVSS 7.5 EPSS 0.3%
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Affects 5 install paths

GHSA-8x88-c5mf-7j5w high CVSS 7.5 EPSS 0.4%
node-tar: Negative tar entry size causes infinite loop in archive replace

Affects 5 install paths

GHSA-9ppj-qmqm-q256 high CVSS 7.5 EPSS 0.3%
node-tar Symlink Path Traversal via Drive-Relative Linkpath

Affects 5 install paths

GHSA-qffp-2rhf-9h96 high CVSS 7.5 EPSS 0.4%
tar has Hardlink Path Traversal via Drive-Relative Linkpath

Affects 5 install paths

GHSA-83g3-92jg-28cx high CVSS 7.1 EPSS 0.3%
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

Affects 5 install paths

GHSA-f5x3-32g6-xq36 medium CVSS 6.5 EPSS 0.9%
Denial of service while parsing a tar file due to lack of folders count validation
GHSA-gvwx-54wh-qm9j medium CVSS 5.3 EPSS 0.3%
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Affects 5 install paths

GHSA-w8wr-v893-vjvp medium CVSS 5.3 EPSS 0.4%
node-tar: Process crash via PAX numeric path type confusion

Affects 5 install paths

GHSA-vmf3-w455-68vh medium CVSS 5.0 EPSS 0.1%
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Affects 5 install paths

2.2.2 → 7.5.19 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 8.8 · 14 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 15.0% · 96th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: package ownership transferred between versions
GHSA-r6q2-hw4h-h46w: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Upgrade tar from 2.2.2 to 7.5.4 or later

View advisory
root → dtslint → @definitelytyped/utils → tar
6.2.1 → 7.5.19 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 8.8 · 11 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 41st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: package ownership transferred between versions
GHSA-r6q2-hw4h-h46w: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Upgrade tar from 6.2.1 to 7.5.4 or later

View advisory
root → pacote → tar
7.4.3 → 7.5.19 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 8.8 · 33 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 41st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r6q2-hw4h-h46w: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Upgrade tar from 7.4.3 to 7.5.4 or later

View advisory
root → pacote → @npmcli/run-script → node-gyp → tar

Blast radius

Paths from project root to tar - which dependencies pulled this package in?

ip @ 1.1.8
root → release-it → proxy-agent → pac-proxy-agent → pac-resolver → ip
2 findings high–low
Trust 15/100 EPSS 8.3%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-78xj-cgh5-2h22 low CVSS 2.5 EPSS 1.6%
NPM IP package incorrectly identifies some private IP addresses as public
ip SSRF improper categorization in isPublic

No fixed version published in OSV

GHSA-2p57-rm9w-gvfp
1.1.8 → 1.1.9 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.6% · 73rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-78xj-cgh5-2h22: NPM IP package incorrectly identifies some private IP addresses as public

Upgrade ip from 1.1.8 to 1.1.9 or later

View advisory
root → release-it → proxy-agent → pac-proxy-agent → pac-resolver → ip

Blast radius

Paths from project root to ip - which dependencies pulled this package in?

vm2 @ 3.9.19 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → release-it → proxy-agent → pac-proxy-agent → pac-resolver → degenerator → vm2
31 findings critical–low
Trust 15/100 EPSS 3.9% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-47x8-96vw-5wg6 critical CVSS 10.0 EPSS 1.0%
vm2 Access to Host Object Enables Sandbox Escape
GHSA-76w7-j9cq-rx2j critical CVSS 10.0 EPSS 0.5%
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
GHSA-m4wx-m65x-ghrr critical CVSS 10.0 EPSS 0.4%
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
GHSA-rp36-8xq3-r6c4 critical CVSS 10.0 EPSS 0.5%
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
GHSA-vwrp-x96c-mhwq critical CVSS 10.0 EPSS 0.8%
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
GHSA-248r-7h7q-cr24 critical CVSS 9.8 EPSS 0.6%
vm2 Has a Sandbox Breakout Using Async Generator
GHSA-55hx-c926-fr95 critical CVSS 9.8 EPSS 0.7%
VM2 Has a Sandbox Escape Issue via SuppressedError
GHSA-6j2x-vhqr-qr7q critical CVSS 9.8 EPSS 0.5%
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
GHSA-9qj6-qjgg-37qq critical CVSS 9.8 EPSS 0.9%
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
GHSA-9vg3-4rfj-wgcm critical CVSS 9.8 EPSS 0.8%
vm2 has Sandbox Breakout Through Null Proto Exception
GHSA-grj5-jjm8-h35p critical CVSS 9.8 EPSS 0.9%
VM2 Sandbox Breakout Through __lookupGetter__
GHSA-qvjj-29qf-hp7p critical CVSS 9.8 EPSS 0.9%
VM2 Has Sandbox Breakout Through Promise Species
GHSA-v37h-5mfm-c47c critical CVSS 9.8 EPSS 1.2%
VM2 Has Sandbox Breakout Through Inspect Function
GHSA-8hg8-63c5-gwmx critical CVSS 9.7 EPSS 0.9%
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
GHSA-m5q2-4fm3-vfqp high CVSS 8.8 EPSS 0.3%
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
GHSA-c4cf-2hgv-2qv6 high CVSS 8.6 EPSS 0.3%
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
GHSA-hw58-p9xv-2mjh high CVSS 8.6 EPSS 0.4%
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
GHSA-r9pm-gxmw-wv6p high CVSS 8.6 EPSS 0.3%
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
GHSA-6785-pvv7-mvg7 high CVSS 7.5 EPSS 0.4%
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
GHSA-mpf8-4hx2-7cjg medium CVSS 6.5 EPSS 0.2%
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
GHSA-v27g-jcqj-v8rw medium CVSS 5.8 EPSS 0.2%
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
GHSA-2cm2-m3w5-gp2f medium CVSS 5.3 EPSS n/a
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
GHSA-wp5r-2gw5-m7q7 medium CVSS 5.3 EPSS 0.2%
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
GHSA-9g8x-92q2-p28f medium CVSS 5.0 EPSS 0.3%
NodeVM observability builtins leak host process and HTTP request data
GHSA-q3fm-4wcw-g57x low CVSS 2.5 EPSS n/a
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
vm2 Sandbox Escape vulnerability

No fixed version published in OSV

GHSA-g644-9gfx-q4q4
3.9.19 → 3.11.4 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 10.0 · 30 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.9% · 89th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • trust veto: package ownership transferred between versions
GHSA-47x8-96vw-5wg6: vm2 Access to Host Object Enables Sandbox Escape

Upgrade vm2 from 3.9.19 to 3.11.0 or later

View advisory
root → release-it → proxy-agent → pac-proxy-agent → pac-resolver → degenerator → vm2

Blast radius

Paths from project root to vm2 - which dependencies pulled this package in?

glob @ 10.4.5
root → pacote → cacache → glob
3 findings high
Trust 30/100 EPSS 3.1%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-5j98-mcp5-4vw2 high CVSS 7.5 EPSS 3.1%
glob CLI: Command injection via -c/--cmd executes matches with shell:true

Affects 3 install paths

10.4.5 → 10.5.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 3.1% · 86th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-5j98-mcp5-4vw2: glob CLI: Command injection via -c/--cmd executes matches with shell:true

Upgrade glob from 10.4.5 to 10.5.0 or later

View advisory
root → pacote → cacache → glob

Blast radius

Paths from project root to glob - which dependencies pulled this package in?

semver @ 5.7.1 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → karma-sauce-launcher → saucelabs → bin-wrapper → bin-version-check → semver
16 findings high
Trust 0/100 EPSS 2.8% ⚠ ownership transferred
MIXED
GHSA-c2qf-rxjj-qqgw high CVSS 7.5 EPSS 2.8%
semver vulnerable to Regular Expression Denial of Service

Affects 16 install paths

5.7.1 → 5.7.2 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 70
Max CVSS 7.5 · 10 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.8% · 84th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-c2qf-rxjj-qqgw: semver vulnerable to Regular Expression Denial of Service

Upgrade semver from 5.7.1 to 5.7.2 or later

View advisory
root → karma-sauce-launcher → saucelabs → bin-wrapper → bin-version-check → semver
6.3.0 → 6.3.1 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 70
Max CVSS 7.5 · 4 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.8% · 84th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-c2qf-rxjj-qqgw: semver vulnerable to Regular Expression Denial of Service

Upgrade semver from 6.3.0 to 6.3.1 or later

View advisory
root → dtslint → dts-critic → semver
7.3.8 → 7.5.2 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.8% · 84th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-c2qf-rxjj-qqgw: semver vulnerable to Regular Expression Denial of Service

Upgrade semver from 7.3.8 to 7.5.2 or later

View advisory
root → pacote → cacache → @npmcli/fs → semver
7.5.1 → 7.5.2 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.8% · 84th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-c2qf-rxjj-qqgw: semver vulnerable to Regular Expression Denial of Service

Upgrade semver from 7.5.1 to 7.5.2 or later

View advisory
root → release-it → semver

Blast radius

Paths from project root to semver - which dependencies pulled this package in?

ajv @ 5.5.2
root → istanbul-instrumenter-loader → schema-utils → ajv
4 findings medium
Trust 0/100 EPSS 2.3%
MIXED
GHSA-2g4f-4pwh-qvx6 medium CVSS 5.0 EPSS 0.5%
ajv has ReDoS when using `$data` option

Affects 3 install paths

5.5.2 → 6.14.0 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.6 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.3% · 81st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv

Upgrade ajv from 5.5.2 to 6.12.3 or later

View advisory
root → istanbul-instrumenter-loader → schema-utils → ajv
6.12.6 → 6.14.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 39th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option

Upgrade ajv from 6.12.6 to 6.14.0 or later

View advisory
root → eslint → @eslint/eslintrc → ajv
8.12.0 → 8.18.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 39th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option

Upgrade ajv from 8.12.0 to 8.18.0 or later

View advisory
root → @commitlint/cli → @commitlint/load → @commitlint/config-validator → ajv

Blast radius

Paths from project root to ajv - which dependencies pulled this package in?

got @ 11.8.3 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → karma-sauce-launcher → saucelabs → got
2 findings medium
Trust 15/100 EPSS 2.2% ⚠ ownership transferred
MIXED
GHSA-pfrx-2q88-qq97 medium CVSS 5.3 EPSS 2.2%
Got allows a redirect to a UNIX socket

Affects 2 install paths

11.8.3 → 11.8.5 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-pfrx-2q88-qq97: Got allows a redirect to a UNIX socket

Upgrade got from 11.8.3 to 11.8.5 or later

View advisory
root → karma-sauce-launcher → saucelabs → got
8.3.2 → 11.8.5 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 20
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more → trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
  • trust veto: package ownership transferred between versions
GHSA-pfrx-2q88-qq97: Got allows a redirect to a UNIX socket

Upgrade got from 8.3.2 to 11.8.5 or later

View advisory
root → karma-sauce-launcher → saucelabs → bin-wrapper → download → got

Blast radius

Paths from project root to got - which dependencies pulled this package in?

handlebars @ 4.7.8
root → auto-changelog → handlebars
8 findings critical–low
Trust 0/100 EPSS 1.8%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-2w6w-674q-4c4q critical CVSS 9.8 EPSS 1.8%
Handlebars.js has JavaScript Injection via AST Type Confusion
GHSA-xjpj-3mr7-gcpf high CVSS 8.8 EPSS 0.3%
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
GHSA-3mfm-83xf-c92r high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
GHSA-xhpv-hc6g-r9c6 high CVSS 8.1 EPSS 0.7%
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
GHSA-9cx6-37pm-9jff high CVSS 7.5 EPSS 0.6%
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
GHSA-7rx3-28cr-v5wh medium CVSS 4.8 EPSS n/a
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
GHSA-2qvq-rjwj-gvw9 medium CVSS 4.7 EPSS 0.3%
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
GHSA-442j-39wm-28r2 low CVSS 3.7 EPSS n/a
Handlebars.js has a Property Access Validation Bypass in container.lookup
4.7.8 → 4.7.9 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 9.8 · 8 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.8% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-2w6w-674q-4c4q: Handlebars.js has JavaScript Injection via AST Type Confusion

Upgrade handlebars from 4.7.8 to 4.7.9 or later

View advisory
root → auto-changelog → handlebars

Blast radius

Paths from project root to handlebars - which dependencies pulled this package in?

form-data @ 2.3.3
root → coveralls → request → form-data
5 findings critical–high
Trust 0/100 EPSS 1.7% ⚠ new maintainer
MIXED
GHSA-fjxv-7rqg-78g4 critical CVSS 9.5 EPSS 1.7%
form-data uses unsafe random function in form-data for choosing boundary

Affects 2 install paths

GHSA-hmw2-7cc7-3qxx high CVSS 7.5 EPSS 0.4%
form-data: CRLF injection in form-data via unescaped multipart field names and filenames

Affects 3 install paths

2.3.3 → 2.5.6 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-fjxv-7rqg-78g4: form-data uses unsafe random function in form-data for choosing boundary

Upgrade form-data from 2.3.3 to 2.5.4 or later

View advisory
root → coveralls → request → form-data
3.0.1 → 3.0.5 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.7% · 75th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-fjxv-7rqg-78g4: form-data uses unsafe random function in form-data for choosing boundary

Upgrade form-data from 3.0.1 to 3.0.4 or later

View advisory
root → karma-sauce-launcher → saucelabs → form-data
4.0.5 → 4.0.6 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-hmw2-7cc7-3qxx: form-data: CRLF injection in form-data via unescaped multipart field names and filenames

Upgrade form-data from 4.0.5 to 4.0.6 or later

View advisory
root → form-data

Blast radius

Paths from project root to form-data - which dependencies pulled this package in?

http-cache-semantics @ 3.8.1
root → release-it → got → cacheable-request → http-cache-semantics
1 finding high
Trust 30/100 EPSS 1.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-rc47-6667-2j5j high CVSS 7.5 EPSS 1.6%
http-cache-semantics vulnerable to Regular Expression Denial of Service
3.8.1 → 4.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.6% · 73rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-rc47-6667-2j5j: http-cache-semantics vulnerable to Regular Expression Denial of Service

Upgrade http-cache-semantics from 3.8.1 to 4.1.1 or later

View advisory
root → release-it → got → cacheable-request → http-cache-semantics

Blast radius

Paths from project root to http-cache-semantics - which dependencies pulled this package in?

braces @ 2.3.2
root → karma → chokidar → braces
4 findings high
Trust 0/100 EPSS 1.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-grv7-fg5c-xmjg high CVSS 7.5 EPSS 1.5%
Uncontrolled resource consumption in braces

Affects 4 install paths

2.3.2 → 3.0.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
GHSA-grv7-fg5c-xmjg: Uncontrolled resource consumption in braces

Upgrade braces from 2.3.2 to 3.0.3 or later

View advisory
root → karma → chokidar → braces
3.0.2 → 3.0.3 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-grv7-fg5c-xmjg: Uncontrolled resource consumption in braces

Upgrade braces from 3.0.2 to 3.0.3 or later

View advisory
root → karma → chokidar → braces

Blast radius

Paths from project root to braces - which dependencies pulled this package in?

semver-regex @ 2.0.0
root → karma-sauce-launcher → saucelabs → bin-wrapper → bin-version-check → bin-version → find-versions → semver-regex
2 findings high–low
Trust 30/100 EPSS 1.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-44c6-4v22-4mhx high CVSS 7.5 EPSS 1.5%
semver-regex Regular Expression Denial of Service (ReDOS)
GHSA-4x5v-gmq8-25ch low CVSS 2.5 EPSS 1.5%
Regular expression denial of service in semver-regex
2.0.0 → 3.1.4 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.5% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-44c6-4v22-4mhx: semver-regex Regular Expression Denial of Service (ReDOS)

Upgrade semver-regex from 2.0.0 to 3.1.3 or later

View advisory
root → karma-sauce-launcher → saucelabs → bin-wrapper → bin-version-check → bin-version → find-versions → semver-regex

Blast radius

Paths from project root to semver-regex - which dependencies pulled this package in?

micromatch @ 3.1.10
root → karma → chokidar → anymatch → micromatch
2 findings medium
Trust 0/100 EPSS 1.4% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-952p-6rrq-rcjv medium CVSS 5.3 EPSS 1.4%
Regular Expression Denial of Service (ReDoS) in micromatch

Affects 2 install paths

3.1.10 → 4.0.8 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.4% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
GHSA-952p-6rrq-rcjv: Regular Expression Denial of Service (ReDoS) in micromatch

Upgrade micromatch from 3.1.10 to 4.0.8 or later

View advisory
root → karma → chokidar → anymatch → micromatch
4.0.5 → 4.0.8 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.4% · 70th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-952p-6rrq-rcjv: Regular Expression Denial of Service (ReDoS) in micromatch

Upgrade micromatch from 4.0.5 to 4.0.8 or later

View advisory
root → release-it → globby → fast-glob → micromatch

Blast radius

Paths from project root to micromatch - which dependencies pulled this package in?

rollup @ 2.79.1
root → rollup
2 findings high–medium
Trust 0/100 EPSS 1.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-mw96-cpmx-2vgc high CVSS 7.5 EPSS 1.4%
Rollup 4 has Arbitrary File Write via Path Traversal
GHSA-gcx4-mw62-g8wm medium CVSS 6.4 EPSS 0.7%
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
2.79.1 → 2.80.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.4% · 69th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-mw96-cpmx-2vgc: Rollup 4 has Arbitrary File Write via Path Traversal

Upgrade rollup from 2.79.1 to 2.80.0 or later

View advisory
root → rollup

Blast radius

Paths from project root to rollup - which dependencies pulled this package in?

ws @ 7.5.7
root → karma-sauce-launcher → webdriverio → puppeteer-core → ws
4 findings high–medium
Trust 0/100 EPSS 1.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-3h5v-q93c-6h6q high CVSS 7.5 EPSS 1.4%
ws affected by a DoS when handling a request with many HTTP headers
GHSA-96hv-2xvq-fx4p high CVSS 7.5 EPSS 0.8%
ws: Memory exhaustion DoS from tiny fragments and data chunks

Affects 2 install paths

7.5.7 → 7.5.11 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.4% · 68th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-3h5v-q93c-6h6q: ws affected by a DoS when handling a request with many HTTP headers

Upgrade ws from 7.5.7 to 7.5.10 or later

View advisory
root → karma-sauce-launcher → webdriverio → puppeteer-core → ws
8.17.1 → 8.21.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.8% · 51st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-96hv-2xvq-fx4p: ws: Memory exhaustion DoS from tiny fragments and data chunks

Upgrade ws from 8.17.1 to 8.21.0 or later

View advisory
root → karma → socket.io → engine.io → ws

Blast radius

Paths from project root to ws - which dependencies pulled this package in?

serialize-javascript @ 4.0.0
root → terser-webpack-plugin → serialize-javascript
5 findings high–medium
Trust 0/100 EPSS 1.1%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-5c6j-r48x-rmvq high CVSS 8.1 EPSS n/a
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Affects 3 install paths

GHSA-qj8w-gfj5-8c6v medium CVSS 5.9 EPSS 0.5%
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
GHSA-76p7-773f-r4q5 medium CVSS 5.4 EPSS 1.1%
Cross-site Scripting (XSS) in serialize-javascript
6.0.0 → 7.0.5 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 8.1 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 1.1% · 61st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-5c6j-r48x-rmvq: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Upgrade serialize-javascript from 6.0.0 to 7.0.3 or later

View advisory
root → mocha → serialize-javascript
4.0.0 → 7.0.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 8.1 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS: n/a
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-5c6j-r48x-rmvq: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Upgrade serialize-javascript from 4.0.0 to 7.0.3 or later

View advisory
root → terser-webpack-plugin → serialize-javascript

Blast radius

Paths from project root to serialize-javascript - which dependencies pulled this package in?

path-to-regexp @ 0.1.10
root → express → path-to-regexp
3 findings high
Trust 0/100 EPSS 0.9% ⚠ new maintainer
MIXED
GHSA-37ch-88jc-xwx2 high CVSS 7.5 EPSS 0.9%
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
GHSA-9wv6-86v2-598j high CVSS 7.5 EPSS 0.9%
path-to-regexp outputs backtracking regular expressions
0.1.10 → 0.1.13 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 56th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-37ch-88jc-xwx2: path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Upgrade path-to-regexp from 0.1.10 to 0.1.13 or later

View advisory
root → express → path-to-regexp
1.8.0 → 1.9.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 56th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-9wv6-86v2-598j: path-to-regexp outputs backtracking regular expressions

Upgrade path-to-regexp from 1.8.0 to 1.9.0 or later

View advisory
root → sinon → nise → path-to-regexp

Blast radius

Paths from project root to path-to-regexp - which dependencies pulled this package in?

cross-spawn @ 5.1.0
root → @commitlint/cli → execa → cross-spawn
2 findings high
Trust 30/100 EPSS 0.9%
MIXED
GHSA-3xgq-45jj-v275 high CVSS 7.5 EPSS 0.9%
Regular Expression Denial of Service (ReDoS) in cross-spawn

Affects 2 install paths

5.1.0 → 6.0.6 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 54th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-3xgq-45jj-v275: Regular Expression Denial of Service (ReDoS) in cross-spawn

Upgrade cross-spawn from 5.1.0 to 6.0.6 or later

View advisory
root → @commitlint/cli → execa → cross-spawn
6.0.5 → 6.0.6 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 54th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-3xgq-45jj-v275: Regular Expression Denial of Service (ReDoS) in cross-spawn

Upgrade cross-spawn from 6.0.5 to 6.0.6 or later

View advisory
root → @commitlint/cli → execa → cross-spawn

Blast radius

Paths from project root to cross-spawn - which dependencies pulled this package in?

flatted @ 3.2.5
root → eslint → file-entry-cache → flat-cache → flatted
2 findings high
Trust 30/100 EPSS 0.8%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-25h7-pfq9-p65f high CVSS 7.5 EPSS 0.8%
flatted vulnerable to unbounded recursion DoS in parse() revive phase
GHSA-rf6f-7fwh-wjgh high CVSS 7.5 EPSS 0.8%
Prototype Pollution via parse() in NodeJS flatted
3.2.5 → 3.4.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.8% · 52nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-25h7-pfq9-p65f: flatted vulnerable to unbounded recursion DoS in parse() revive phase

Upgrade flatted from 3.2.5 to 3.4.0 or later

View advisory
root → eslint → file-entry-cache → flat-cache → flatted

Blast radius

Paths from project root to flatted - which dependencies pulled this package in?

@octokit/request @ 6.2.8
root → release-it → @octokit/rest → @octokit/core → @octokit/request
1 finding medium
Trust 0/100 EPSS 0.8%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-rmvr-2pp2-xj38 medium CVSS 5.3 EPSS 0.8%
@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
6.2.8 → 8.4.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.8% · 51st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-rmvr-2pp2-xj38: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Upgrade @octokit/request from 6.2.8 to 8.4.1 or later

View advisory
root → release-it → @octokit/rest → @octokit/core → @octokit/request

Blast radius

Paths from project root to @octokit/request - which dependencies pulled this package in?

multer @ 1.4.4
root → multer
8 findings high
Trust 0/100 EPSS 0.7% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-44fp-w29j-9vj5 high CVSS 7.5 EPSS 0.7%
Multer vulnerable to Denial of Service via memory leaks from unclosed streams
GHSA-4pg4-qvpc-4q3h high CVSS 7.5 EPSS 0.7%
Multer vulnerable to Denial of Service from maliciously crafted requests
GHSA-5528-5vmv-3xc2 high CVSS 7.5 EPSS 0.7%
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
GHSA-72gw-mp4g-v24j high CVSS 7.5 EPSS 0.3%
Multer vulnerable to Denial of Service via deeply nested field names
GHSA-fjgf-rc76-4x9p high CVSS 7.5 EPSS 0.6%
Multer vulnerable to Denial of Service via unhandled exception from malformed request
GHSA-g5hg-p3ph-g8qg high CVSS 7.5 EPSS 0.4%
Multer vulnerable to Denial of Service via unhandled exception
GHSA-v52c-386h-88mc high CVSS 7.5 EPSS 0.7%
Multer vulnerable to Denial of Service via resource exhaustion
GHSA-xf7r-hgr6-v32p high CVSS 7.5 EPSS 0.7%
Multer vulnerable to Denial of Service via incomplete cleanup
1.4.4 → 2.2.0 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 35
Max CVSS 7.5 · 8 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.7% · 50th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more → trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • major version bump requires human review (never auto-merge)
  • trust veto: new maintainer added
GHSA-44fp-w29j-9vj5: Multer vulnerable to Denial of Service via memory leaks from unclosed streams

Upgrade multer from 1.4.4 to 2.0.0 or later

View advisory
root → multer

Blast radius

Paths from project root to multer - which dependencies pulled this package in?

sha.js @ 2.4.11
root → create-hash → sha.js
1 finding critical
Trust 0/100 EPSS 0.7% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-95m3-7q98-8xr5 critical CVSS 9.1 EPSS 0.7%
sha.js is missing type checks leading to hash rewind and passing on crafted data
2.4.11 → 2.4.12 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.1 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.7% · 48th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-95m3-7q98-8xr5: sha.js is missing type checks leading to hash rewind and passing on crafted data

Upgrade sha.js from 2.4.11 to 2.4.12 or later

View advisory
root → create-hash → sha.js

Blast radius

Paths from project root to sha.js - which dependencies pulled this package in?

@octokit/plugin-paginate-rest @ 6.1.2
root → release-it → @octokit/rest → @octokit/plugin-paginate-rest
1 finding medium
Trust 0/100 EPSS 0.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-h5c3-5r3r-rr8q medium CVSS 5.3 EPSS 0.6%
@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
6.1.2 → 9.2.2 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 45th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-h5c3-5r3r-rr8q: @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Upgrade @octokit/plugin-paginate-rest from 6.1.2 to 9.2.2 or later

View advisory
root → release-it → @octokit/rest → @octokit/plugin-paginate-rest

Blast radius

Paths from project root to @octokit/plugin-paginate-rest - which dependencies pulled this package in?

@octokit/request-error @ 3.0.3
root → release-it → @octokit/rest → @octokit/core → @octokit/request-error
1 finding medium
Trust 0/100 EPSS 0.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-xx4v-prfh-6cgc medium CVSS 5.3 EPSS 0.6%
@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
3.0.3 → 5.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 45th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-xx4v-prfh-6cgc: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Upgrade @octokit/request-error from 3.0.3 to 5.1.1 or later

View advisory
root → release-it → @octokit/rest → @octokit/core → @octokit/request-error

Blast radius

Paths from project root to @octokit/request-error - which dependencies pulled this package in?

node-forge @ 1.3.3
root → selfsigned → node-forge
4 findings high
Trust 0/100 EPSS 0.6%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-5m6q-g25r-mvwx high CVSS 7.5 EPSS 0.6%
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
GHSA-ppp5-5v6c-4jwp high CVSS 7.5 EPSS 0.3%
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
GHSA-q67f-28xg-22rw high CVSS 7.5 EPSS 0.3%
Forge has signature forgery in Ed25519 due to missing S > L check
GHSA-2328-f5f3-gj25 high CVSS 7.4 EPSS 0.3%
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
1.3.3 → 1.4.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 4 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 44th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-5m6q-g25r-mvwx: Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

Upgrade node-forge from 1.3.3 to 1.4.0 or later

View advisory
root → selfsigned → node-forge

Blast radius

Paths from project root to node-forge - which dependencies pulled this package in?

diff @ 3.5.0
root → dtslint → tslint → diff
4 findings low
Trust 30/100 EPSS 0.6% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-73rr-hh4g-fpgx low CVSS 2.5 EPSS 0.6%
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Affects 4 install paths

3.5.0 → 3.5.1 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 2.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 3.5.0 to 3.5.1 or later

View advisory
root → dtslint → tslint → diff
4.0.2 → 4.0.4 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 4.0.2 to 4.0.4 or later

View advisory
root → @commitlint/cli → @commitlint/load → ts-node → diff
5.0.0 → 5.2.2 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 5.0.0 to 5.2.2 or later

View advisory
root → mocha → diff

Blast radius

Paths from project root to diff - which dependencies pulled this package in?

es5-ext @ 0.10.61
root → memoizee → d → es5-ext
1 finding low
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-4gmj-3p3h-gm8h low CVSS 2.5 EPSS 0.5%
es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`
0.10.61 → 0.10.63 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 41st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-4gmj-3p3h-gm8h: es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Upgrade es5-ext from 0.10.61 to 0.10.63 or later

View advisory
root → memoizee → d → es5-ext

Blast radius

Paths from project root to es5-ext - which dependencies pulled this package in?

basic-ftp @ 5.0.4
root → release-it → proxy-agent → pac-proxy-agent → get-uri → basic-ftp
4 findings critical–high
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-5rq4-664w-9x2c critical CVSS 9.1 EPSS 0.5%
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method
GHSA-6v7q-wjvx-w8wg high CVSS 8.2 EPSS n/a
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
GHSA-rp42-5vxx-qpwr high CVSS 7.5 EPSS 0.3%
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
GHSA-rpmf-866q-6p89 high CVSS 7.5 EPSS 0.5%
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
5.0.4 → 5.3.1 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 9.1 · 4 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 41st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-5rq4-664w-9x2c: Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

Upgrade basic-ftp from 5.0.4 to 5.2.0 or later

View advisory
root → release-it → proxy-agent → pac-proxy-agent → get-uri → basic-ftp

Blast radius

Paths from project root to basic-ftp - which dependencies pulled this package in?

minimatch @ 3.1.2
root → eslint → @eslint/eslintrc → minimatch
24 findings high
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-23c5-xmqv-rm74 high CVSS 7.5 EPSS 0.5%
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Affects 8 install paths

GHSA-3ppc-4f35-3m26 high CVSS 7.5 EPSS 0.5%
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Affects 8 install paths

GHSA-7r86-cg39-jmmj high CVSS 7.5 EPSS 0.5%
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Affects 8 install paths

3.1.2 → 3.1.4 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 3.1.2 to 3.1.4 or later

View advisory
root → eslint → @eslint/eslintrc → minimatch
5.0.1 → 5.1.8 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 5.0.1 to 5.1.8 or later

View advisory
root → @rollup/plugin-commonjs → glob → minimatch
9.0.5 → 9.0.7 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 18 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-23c5-xmqv-rm74: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Upgrade minimatch from 9.0.5 to 9.0.7 or later

View advisory
root → @rollup/plugin-commonjs → glob → minimatch

Blast radius

Paths from project root to minimatch - which dependencies pulled this package in?

socket.io-parser @ 4.2.4
root → karma → socket.io → socket.io-parser
1 finding high
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-677m-j7p3-52f9 high CVSS 7.5 EPSS 0.5%
socket.io allows an unbounded number of binary attachments
4.2.4 → 4.2.6 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-677m-j7p3-52f9: socket.io allows an unbounded number of binary attachments

Upgrade socket.io-parser from 4.2.4 to 4.2.6 or later

View advisory
root → karma → socket.io → socket.io-parser

Blast radius

Paths from project root to socket.io-parser - which dependencies pulled this package in?

browserify-sign @ 4.2.1
root → crypto-browserify → browserify-sign
1 finding high
Trust 0/100 EPSS 0.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-x9w5-v3q2-3rhw high CVSS 7.5 EPSS 0.5%
browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack
4.2.1 → 4.2.2 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 40th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-x9w5-v3q2-3rhw: browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack

Upgrade browserify-sign from 4.2.1 to 4.2.2 or later

View advisory
root → crypto-browserify → browserify-sign

Blast radius

Paths from project root to browserify-sign - which dependencies pulled this package in?

cipher-base @ 1.0.4
root → browserify-aes → cipher-base
1 finding critical
Trust 30/100 EPSS 0.5% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-cpq7-6gpm-g9rc critical CVSS 9.1 EPSS 0.5%
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
1.0.4 → 1.0.5 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.1 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 39th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-cpq7-6gpm-g9rc: cipher-base is missing type checks, leading to hash rewind and passing on crafted data

Upgrade cipher-base from 1.0.4 to 1.0.5 or later

View advisory
root → browserify-aes → cipher-base

Blast radius

Paths from project root to cipher-base - which dependencies pulled this package in?

follow-redirects @ 1.15.11
root → karma → http-proxy → follow-redirects
1 finding medium
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-r4q5-vmmm-2653 medium CVSS 5.0 EPSS 0.5%
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
1.15.11 → 1.16.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 38th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r4q5-vmmm-2653: follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets

Upgrade follow-redirects from 1.15.11 to 1.16.0 or later

View advisory
root → karma → http-proxy → follow-redirects

Blast radius

Paths from project root to follow-redirects - which dependencies pulled this package in?

@babel/helpers @ 7.23.9
root → @babel/core → @babel/helpers
1 finding medium
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-968p-4wvh-cqc8 medium CVSS 6.2 EPSS 0.5%
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
7.23.9 → 7.26.10 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.2 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 38th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-968p-4wvh-cqc8: Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups

Upgrade @babel/helpers from 7.23.9 to 7.26.10 or later

View advisory
root → @babel/core → @babel/helpers

Blast radius

Paths from project root to @babel/helpers - which dependencies pulled this package in?

@babel/runtime @ 7.23.9
root → @babel/preset-env → @babel/plugin-transform-regenerator → regenerator-transform → @babel/runtime
1 finding medium
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-968p-4wvh-cqc8 medium CVSS 6.2 EPSS 0.5%
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
7.23.9 → 7.26.10 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.2 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 38th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-968p-4wvh-cqc8: Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups

Upgrade @babel/runtime from 7.23.9 to 7.26.10 or later

View advisory
root → @babel/preset-env → @babel/plugin-transform-regenerator → regenerator-transform → @babel/runtime

Blast radius

Paths from project root to @babel/runtime - which dependencies pulled this package in?

qs @ 6.13.0
root → body-parser → qs
4 findings medium–low
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-q8mj-m7cp-5q26 medium CVSS 5.3 EPSS 0.4%
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
GHSA-6rw7-vpxm-498p low CVSS 3.7 EPSS 0.4%
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

Affects 2 install paths

GHSA-w7fw-mjwx-w883 low CVSS 3.7 EPSS 0.5%
qs's arrayLimit bypass in comma parsing allows denial of service
6.13.0 → 6.15.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 38th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-q8mj-m7cp-5q26: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Upgrade qs from 6.13.0 to 6.15.2 or later

View advisory
root → body-parser → qs
6.5.3 → 6.14.1 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 3.7 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-6rw7-vpxm-498p: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

Upgrade qs from 6.5.3 to 6.14.1 or later

View advisory
root → coveralls → request → qs

Blast radius

Paths from project root to qs - which dependencies pulled this package in?

ip-address @ 10.0.1
root → release-it → proxy-agent → socks-proxy-agent → socks → ip-address
1 finding medium
Trust 30/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-v2v4-37r5-5v8g medium CVSS 5.0 EPSS 0.5%
ip-address has XSS in Address6 HTML-emitting methods
10.0.1 → 10.1.1 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.0 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-v2v4-37r5-5v8g: ip-address has XSS in Address6 HTML-emitting methods

Upgrade ip-address from 10.0.1 to 10.1.1 or later

View advisory
root → release-it → proxy-agent → socks-proxy-agent → socks → ip-address

Blast radius

Paths from project root to ip-address - which dependencies pulled this package in?

bn.js @ 4.12.0
root → elliptic → bn.js
7 findings medium
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-378v-28hj-76wf medium CVSS 5.3 EPSS 0.5%
bn.js affected by an infinite loop

Affects 7 install paths

4.12.0 → 4.12.3 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 6 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-378v-28hj-76wf: bn.js affected by an infinite loop

Upgrade bn.js from 4.12.0 to 4.12.3 or later

View advisory
root → elliptic → bn.js
5.2.0 → 5.2.3 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-378v-28hj-76wf: bn.js affected by an infinite loop

Upgrade bn.js from 5.2.0 to 5.2.3 or later

View advisory
root → browserify-rsa → bn.js

Blast radius

Paths from project root to bn.js - which dependencies pulled this package in?

brace-expansion @ 1.1.11
root → eslint → minimatch → brace-expansion
18 findings medium–low
Trust 0/100 EPSS 0.5%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-f886-m6hf-6m8v medium CVSS 6.5 EPSS 0.4%
brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Affects 8 install paths

GHSA-3jxr-9vmj-r5cp medium CVSS 5.3 EPSS 0.4%
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Affects 8 install paths

GHSA-v6h2-p8h4-qcjw low CVSS 3.1 EPSS 0.5%
brace-expansion Regular Expression Denial of Service vulnerability

Affects 2 install paths

1.1.11 → 1.1.16 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 1.1.11 to 1.1.13 or later

View advisory
root → eslint → minimatch → brace-expansion
2.0.1 → 2.1.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 2.0.1 to 2.0.3 or later

View advisory
root → eslint → minimatch → brace-expansion
2.0.2 → 2.1.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 6.5 · 12 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 34th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-f886-m6hf-6m8v: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Upgrade brace-expansion from 2.0.2 to 2.0.3 or later

View advisory
root → eslint → minimatch → brace-expansion

Blast radius

Paths from project root to brace-expansion - which dependencies pulled this package in?

js-yaml @ 3.14.2
root → coveralls → js-yaml
13 findings high–medium
Trust 30/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-52cp-r559-cp3m high CVSS 7.5 EPSS 0.4%
js-yaml: YAML merge-key chains can force quadratic CPU consumption

Affects 6 install paths

GHSA-h67p-54hq-rp68 medium CVSS 5.3 EPSS 0.3%
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Affects 6 install paths

4.1.0 → 4.3.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 3 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 4.1.0 to 4.3.0 or later

View advisory
root → mocha → js-yaml
3.14.2 → 3.15.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 29th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 3.14.2 to 3.15.0 or later

View advisory
root → coveralls → js-yaml
4.1.1 → 4.3.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 8 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 29th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 4.1.1 to 4.3.0 or later

View advisory
root → eslint → @eslint/eslintrc → js-yaml

Blast radius

Paths from project root to js-yaml - which dependencies pulled this package in?

picomatch @ 2.3.1
root → @rollup/plugin-babel → @rollup/pluginutils → picomatch
4 findings high–medium
Trust 0/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-c2c7-rcm5-vvqj high CVSS 7.5 EPSS 0.4%
Picomatch has a ReDoS vulnerability via extglob quantifiers

Affects 2 install paths

GHSA-3v7f-55p6-f55p medium CVSS 5.3 EPSS 0.4%
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Affects 2 install paths

2.3.1 → 2.3.2 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-c2c7-rcm5-vvqj: Picomatch has a ReDoS vulnerability via extglob quantifiers

Upgrade picomatch from 2.3.1 to 2.3.2 or later

View advisory
root → @rollup/plugin-babel → @rollup/pluginutils → picomatch
4.0.3 → 4.0.4 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 33rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-c2c7-rcm5-vvqj: Picomatch has a ReDoS vulnerability via extglob quantifiers

Upgrade picomatch from 4.0.3 to 4.0.4 or later

View advisory
root → pacote → @npmcli/run-script → node-gyp → tinyglobby → picomatch

Blast radius

Paths from project root to picomatch - which dependencies pulled this package in?

pbkdf2 @ 3.1.2
root → crypto-browserify → pbkdf2
2 findings critical
Trust 0/100 EPSS 0.4% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-h7cp-r72f-jxh6 critical CVSS 9.5 EPSS 0.4%
pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos
GHSA-v62p-rq8g-8h59 critical CVSS 9.5 EPSS 0.4%
pbkdf2 silently disregards Uint8Array input, returning static keys
3.1.2 → 3.1.3 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 31st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-h7cp-r72f-jxh6: pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos

Upgrade pbkdf2 from 3.1.2 to 3.1.3 or later

View advisory
root → crypto-browserify → pbkdf2

Blast radius

Paths from project root to pbkdf2 - which dependencies pulled this package in?

formidable @ 2.1.2
root → formidable
1 finding low
Trust 0/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-75v8-2h7p-7m2m low CVSS 3.1 EPSS 0.4%
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
2.1.2 → 2.1.3 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 3.1 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 30th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-75v8-2h7p-7m2m: Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

Upgrade formidable from 2.1.2 to 2.1.3 or later

View advisory
root → formidable

Blast radius

Paths from project root to formidable - which dependencies pulled this package in?

engine.io @ 6.6.2
root → karma → socket.io → engine.io
1 finding high
Trust 0/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-r635-g3xr-vw7x high CVSS 7.5 EPSS 0.4%
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
6.6.2 → 6.6.7 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 27th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r635-g3xr-vw7x: Socket.IO: Engine.IO Polling Transport Connection Exhaustion

Upgrade engine.io from 6.6.2 to 6.6.7 or later

View advisory
root → karma → socket.io → engine.io

Blast radius

Paths from project root to engine.io - which dependencies pulled this package in?

tmp @ 0.0.33
root → release-it → inquirer → external-editor → tmp
4 findings high–low
Trust 30/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-ph9p-34f9-6g65 high CVSS 7.5 EPSS 0.4%
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Affects 2 install paths

GHSA-52f5-9888-hmc6 low CVSS 2.5 EPSS 0.3%
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

Affects 2 install paths

0.0.33 → 0.2.6 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 27th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-ph9p-34f9-6g65: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Upgrade tmp from 0.0.33 to 0.2.6 or later

View advisory
root → release-it → inquirer → external-editor → tmp
0.2.1 → 0.2.6 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 27th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-ph9p-34f9-6g65: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Upgrade tmp from 0.2.1 to 0.2.6 or later

View advisory
root → dtslint → dts-critic → tmp

Blast radius

Paths from project root to tmp - which dependencies pulled this package in?

uuid @ 3.4.0
root → coveralls → request → uuid
2 findings high
Trust 0/100 EPSS 0.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-w5hq-g745-h8pq high CVSS 7.5 EPSS 0.3%
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Affects 2 install paths

3.4.0 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 3.4.0 to 11.1.1 or later

View advisory
root → coveralls → request → uuid
8.3.2 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 8.3.2 to 11.1.1 or later

View advisory
root → karma-sauce-launcher → webdriverio → devtools → uuid

Blast radius

Paths from project root to uuid - which dependencies pulled this package in?

@sigstore/core @ 2.0.0
root → pacote → sigstore → @sigstore/sign → @sigstore/core
1 finding medium
Trust 0/100 EPSS 0.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-jfc7-64v2-mr8c medium CVSS 5.4 EPSS 0.3%
@sigstore/core has DSSE payloadType type-binding failure
2.0.0 → 3.2.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 5.4 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 18th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-jfc7-64v2-mr8c: @sigstore/core has DSSE payloadType type-binding failure

Upgrade @sigstore/core from 2.0.0 to 3.2.1 or later

View advisory
root → pacote → sigstore → @sigstore/sign → @sigstore/core

Blast radius

Paths from project root to @sigstore/core - which dependencies pulled this package in?

body-parser @ 1.20.3
root → express → body-parser
1 finding low
Trust 0/100 EPSS 0.2% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-v422-hmwv-36x6 low CVSS 3.7 EPSS 0.2%
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
1.20.3 → 1.20.6 patch
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 3.7 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.2% · 16th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-v422-hmwv-36x6: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

Upgrade body-parser from 1.20.3 to 1.20.6 or later

View advisory
root → express → body-parser

Blast radius

Paths from project root to body-parser - which dependencies pulled this package in?

sigstore @ 3.1.0
root → pacote → sigstore
1 finding high
Trust 0/100 EPSS 0.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-52v5-jr5w-gjxr high CVSS 7.5 EPSS 0.2%
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
3.1.0 → 4.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.2% · 8th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-52v5-jr5w-gjxr: sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Upgrade sigstore from 3.1.0 to 4.1.1 or later

View advisory
root → pacote → sigstore

Blast radius

Paths from project root to sigstore - which dependencies pulled this package in?

elliptic @ 6.6.0
root → browserify-sign → elliptic
2 findings critical–medium
Trust 30/100 EPSS 0.2%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-vjh7-7g9h-fjfh critical CVSS 9.5 EPSS n/a
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
Elliptic Uses a Cryptographic Primitive with a Risky Implementation

No fixed version published in OSV

GHSA-848j-6mx2-7j84
6.6.0 → 6.6.1 patch
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 9.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS: n/a
  • patch-level upgrade; trust signals unchanged; CI verifies tests
GHSA-vjh7-7g9h-fjfh: Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)

Upgrade elliptic from 6.6.0 to 6.6.1 or later

View advisory
root → browserify-sign → elliptic

Blast radius

Paths from project root to elliptic - which dependencies pulled this package in?

@babel/plugin-transform-modules-systemjs @ 7.23.9
root → @babel/preset-env → @babel/plugin-transform-modules-systemjs
1 finding high
Trust 0/100 EPSS 0.1%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-fv7c-fp4j-7gwp high CVSS 8.8 EPSS 0.1%
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
7.23.9 → 7.29.4 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 8.8 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.1% · 2nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-fv7c-fp4j-7gwp: @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input

Upgrade @babel/plugin-transform-modules-systemjs from 7.23.9 to 7.29.4 or later

View advisory
root → @babel/preset-env → @babel/plugin-transform-modules-systemjs

Blast radius

Paths from project root to @babel/plugin-transform-modules-systemjs - which dependencies pulled this package in?

@babel/core @ 7.23.9
root → @babel/core
1 finding low
Trust 0/100 EPSS 0.1%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-4x5r-pxfx-6jf8 low CVSS 3.2 EPSS 0.1%
@babel/core: Arbitrary File Read via sourceMappingURL Comment
7.23.9 → 7.29.6 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 3.2 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.1% · 1st percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-4x5r-pxfx-6jf8: @babel/core: Arbitrary File Read via sourceMappingURL Comment

Upgrade @babel/core from 7.23.9 to 7.29.6 or later

View advisory
root → @babel/core

Blast radius

Paths from project root to @babel/core - which dependencies pulled this package in?

Package status

1767 packages scanned.

  • 37 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
  • 4 Packages with no automated fix +3 More with unfixable findings alongside fixable ones
  • 46 Auto-merge candidates

Review auto-merge candidates and open PRs in a guided flow.

Glossary

What the labels and signals mean.

Trust Save
A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
AUTO-MERGE
Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
REVIEW
Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
DECLINE
Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major
Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer
Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred
Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.
pipeline.test_reality
Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.
CVSS
Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
EPSS
Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
KEV
CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
Project Risk Score (PRS)
A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.

Dependency graph

Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).